Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
Exploit-DB✓ VexDay Proof
Pandora FMS 3.1 - Authentication Bypass / Arbitrary File Upload (Metasploit)
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RIESGO
abrir ↗Exploit-DB
Sefrengo CMS 1.6.0 - SQL Injection
Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrator
23RIESGO
abrir ↗Exploit-DB
Microweber CMS 0.95 - SQL Injection
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB
Pirelli ADSL2/2+ Wireless Router P.DGA4001N - Information Disclosure
The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly rest
50RIESGO
abrir ↗Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect
23RIESGO
abrir ↗Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB
Nexus 5 Android 5.0 - Local Privilege Escalation
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir ↗Metasploit300
McAfee ePolicy Orchestrator Authenticated XXE Credentials Exposure
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers'
23RIESGO
abrir ↗Metasploit300
McAfee ePolicy Orchestrator Authenticated XXE Credentials Exposure
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x
23RIESGO
abrir ↗Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute
23RIESGO
abrir ↗Exploit-DB
SkinCrafter3 vs2005 3.8.1.0 - Multiple ActiveX Buffer Overflows
Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'welcome' Remote Command Execution (Metasploit)
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RIESGO
abrir ↗Metasploit600
ASUS infosvr Auth Bypass Command Execution
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASUSWRT 3.0.0.4.376_1071 - LAN Backdoor Command Execution
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir ↗Exploit-DB
Crea8Social 2.0 - Cross-Site Scripting Change Interface
Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e107 2 Bootstrap CMS - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Exploit-DB
PhotoPost < 4.85 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB
PhotoPost < 4.85 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB
ReviewPost < 2.84 - Multiple Vulnerabilities
ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review fil
23RIESGO
abrir ↗Exploit-DB
ReviewPost < 2.84 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject a
23RIESGO
abrir ↗Exploit-DB
ReviewPost < 2.84 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB
Absolut Engine 1.73 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.1 (x86/x64) - 'ahcache.sys' NtApphelpCacheControl Privilege Escalation
The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1,
43RIESGO
abrir ↗Exploit-DB
Absolut Engine 1.73 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.7
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProjectSend - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Social Microblogging PRO 1.5 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Metasploit300
ManageEngine Desktop Central Administrator Account Creation
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at
60RIESGO
abrir ↗Exploit-DB
PHP-Calendar < 0.10.1 - Arbitrary File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth o
28RIESGO
abrir ↗Exploit-DB
WHM.AutoPilot < 2.4.6.5 - Multiple Vulnerabilities
WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php s
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.